Search CVE reports


Toggle filters

11 – 18 of 18 results


CVE-2017-5339

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2
Show less packages

CVE-2017-5338

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2
Show less packages

CVE-2016-8569

Low priority

Some fixes available 2 of 5

The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected
Show less packages

CVE-2016-8568

Medium priority

Some fixes available 2 of 5

The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected
Show less packages

CVE-2016-10130

Medium priority
Vulnerable

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-10129

Medium priority
Vulnerable

The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-10128

Medium priority
Vulnerable

Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted...

1 affected package

libgit2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Not affected
Show less packages

CVE-2014-9390

Medium priority

Some fixes available 27 of 42

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before...

5 affected packages

libgit2, jgit, git-core, git, mercurial

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgit2 Not affected Not affected Not affected Not affected
jgit Not affected Not affected Not affected Not affected
git-core Not in release Not in release Not in release Not in release
git Fixed Fixed Fixed Fixed
mercurial Not affected Not affected Not affected Not affected
Show less packages